SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

The package is likely malware due to suspicious preinstall script and bash persistence behavior in multiple files.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The package.json includes a preinstall script that executes node setup_bun.js, which is highly unusual and a potential entry point for malicious code execution before installation. Furthermore, both bun_environment.js and setup_bun.js files trigger the bash_persist_persistent YARA rule, indicating access to multiple bash startup files, a common persistence technique used by malware. The combination of these factors strongly suggests malicious intent.

@quick-start-soft/quick-remove-image-background@1.4.2511142126Malicious
Verified
Analysed at: 11/24/25, 3:35 AM
Source: https://registry.npmjs.org/@quick-start-soft/quick-remove-image-background/-/quick-remove-image-background-1.4.2511142126.tgz
SHA256: 27010b5d7732ee0a3518e96cb579c357fcf5ca4ceee86a75fe7e25cf2399d2fb
Confidence: High